CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6893
7.5 HIGH

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local …

Aug 8, 2024
CVE-2024-6891
8.8 HIGH

Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

Aug 8, 2024
CVE-2024-6890
8.8 HIGH

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password …

Aug 7, 2024
CVE-2024-6707
8.8 HIGH

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

Aug 7, 2024
CVE-2024-7585
8.8 HIGH

A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as critical. Affected by this vulnerability is the function formApPortalWebAuth of the file /goform/apPortalAuth. …

Aug 7, 2024
CVE-2024-7584
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formApPortalPhoneAuth of the file /goform/apPortalPhoneAuth. The manipulation of …

Aug 7, 2024
CVE-2024-7143
8.3 HIGH

A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, …

Aug 7, 2024
CVE-2024-20451
7.5 HIGH

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow …

Aug 7, 2024
CVE-2024-7583
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda i22 1.0.0.3(4687). This issue affects the function formApPortalOneKeyAuth of the file /goform/apPortalOneKeyAuth. The …

Aug 7, 2024
CVE-2024-7582
8.8 HIGH

A vulnerability classified as critical was found in Tenda i22 1.0.0.3(4687). This vulnerability affects the function formApPortalAccessCodeAuth of the file /goform/apPortalAccessCodeAuth. The manipulation of the …

Aug 7, 2024
CVE-2024-41309
7.8 HIGH

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level …

Aug 7, 2024
CVE-2024-41308
7.8 HIGH

An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges …

Aug 7, 2024
CVE-2024-7581
8.8 HIGH

A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the …

Aug 7, 2024
CVE-2024-42005
7.3 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to …

Aug 7, 2024
CVE-2024-41991
7.5 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject …

Aug 7, 2024
CVE-2024-41990
7.5 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service …

Aug 7, 2024
CVE-2024-41989
7.5 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given …

Aug 7, 2024
CVE-2024-43199
7.8 HIGH

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

Aug 7, 2024
CVE-2024-43044
8.8 HIGH

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` …

Aug 7, 2024
CVE-2024-7578
7.3 HIGH

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file …

Aug 7, 2024
CVE-2024-7265
8.8 HIGH

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any …

Aug 7, 2024
CVE-2024-6522
8.5 HIGH

The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX …

Aug 7, 2024
CVE-2024-7553
7.3 HIGH

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result …

Aug 7, 2024
CVE-2024-5290
8.8 HIGH

An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to …

Aug 7, 2024
CVE-2024-42062
7.2 HIGH

CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys …

Aug 7, 2024
CVE-2024-36132
7.5 HIGH

Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

Aug 7, 2024
CVE-2024-36131
8.8 HIGH

An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating …

Aug 7, 2024
CVE-2024-34623
7.8 HIGH

Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.

Aug 7, 2024
CVE-2024-34622
7.8 HIGH

Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.

Aug 7, 2024
CVE-2024-34620
8.4 HIGH

Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.

Aug 7, 2024
CVE-2024-34619
7.5 HIGH

Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required …

Aug 7, 2024
CVE-2024-34614
7.3 HIGH

Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

Aug 7, 2024
CVE-2024-34612
7.3 HIGH

Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

Aug 7, 2024
CVE-2024-38206
8.5 HIGH

An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.

Aug 6, 2024
CVE-2024-38166
8.2 HIGH

An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a …

Aug 6, 2024
CVE-2024-7550
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 6, 2024
CVE-2024-7536
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 6, 2024
CVE-2024-7535
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 6, 2024
CVE-2024-7534
8.8 HIGH

Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 6, 2024
CVE-2024-7533
8.8 HIGH

Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Aug 6, 2024
CVE-2024-7532
8.8 HIGH

Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Aug 6, 2024
CVE-2024-42219
7.8 HIGH

1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.

Aug 6, 2024
CVE-2024-28739
7.2 HIGH

An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

Aug 6, 2024
CVE-2024-42347
7.7 HIGH

matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to …

Aug 6, 2024
CVE-2024-7502
7.8 HIGH

A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

Aug 6, 2024
CVE-2024-7000
8.8 HIGH

Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Aug 6, 2024
CVE-2024-6998
8.8 HIGH

Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI …

Aug 6, 2024
CVE-2024-6997
8.8 HIGH

Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Aug 6, 2024
CVE-2024-6994
8.8 HIGH

Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 6, 2024
CVE-2024-6991
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.